capt1mc
2008-12-16, 02:17
I have had Smitfraud-c.gp on my computer for some time and have tried numerous ways to get rid of it on my own and it just comes back after restart. If I block it with Avast it must be still running because the computer starts to lag and gets slower with time. Then it seems better, but slows again.
Here's what happened: I downloaded Acronis True Image from a web site and Smitfraud-c.gp, Zlob and a couple other viruses came with it. I managed to clean the rest off except Smitfraud-c.gp.
I have a file named windows\system\explorer.exe which is obviously a fake explorer. I used "find" in registry for windows\system\explorer.exe and deleted the registry items it found and once again tried to delete the file itself, did not work. I booted the computer and tried to delete it with "del c:\windows\system\explorer.exe" and this did not work either. I have searched the web for hours trying to find some resolution to this and nothing seems to work. Reading through different posts trying to fix this by myself I read about Smitrem and dl'd that and ran it, but it did not fix the prob.
Here's where I'm at: Today I ran some programs I usually use to clean up harddrives. Here's the results of the scans and a HJT log:
--------------- Avast:
File name: C:\WINDOWS\SVCHOST.EXE
Malware Name: Wi????????????????e
Malware Type: Rootkit:hidden process
VPS version: 081210-0, 12/10/2008
File name: C:\WINDOWS\svchost.exe
Malware Name: Win32:Rootkit-gen [Rtk]
Malware Type: Rootkit
VPS version: 081210-0, 12/10/2008
--------------- Panda Active Scan:
ANALYSIS: 2008-12-15 11:22:41
PROTECTIONS: 2
MALWARE: 9
SUSPECTS: 2
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
avast! antivirus 4.8.1296 [VPS 081215-0] 4.8.1296 Yes Yes
iolo AntiVirus 1.5 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00122168 Application/Restart HackTools No 0 Yes No C:\WINDOWS\system32\Tools\Restart.exe
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Cookies\chris@server.iad.liveperson[2].txt
00207338 Cookie/Target TrackingCookie No 0 Yes No C:\Documents and Settings\Guest\Cookies\guest@target[1].txt
00207862 Cookie/did-it TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Cookies\chris@did-it[1].txt
00366244 Application/NirCmd.A HackTools No 0 Yes No C:\fixwareout\FindT\nircmd.exe
00520936 Application/ViewPoint HackTools No 0 Yes No C:\Program Files\Trend Micro\HijackThis\backups\backup-20080926-130701-650.dll
02916589 Application/PassRock HackTools No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP79\A0017739.exe
03738686 Generic Malware Virus/Trojan No 0 Yes No C:\SDFix\catchme.exe
03738686 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025852.exe[C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025852.exe][SDFix\apps\Cghtme.exe]
03738686 Generic Malware Virus/Trojan No 0 Yes No C:\SDFix\apps\Cghtme.exe
03738686 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025852.exe[C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025852.exe][SDFix\catchme.exe]
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025608.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025646.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025596.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP81\A0023427.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\SDFix\backups\backups.zip[backups/svchost.exe]
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP90\A0026430.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP90\A0027468.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP90\A0027472.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP81\A0023440.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location )5
;===================================================================================================================================================================================
No C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\ViewBar.dll )5
No C:\Program Files\Warcraft III\cdkey.exe )5
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
--------------- Housecall:
Found nothing
---------------MBAM:
Malwarebytes' Anti-Malware 1.31
Database version: 1467
Windows 5.1.2600 Service Pack 3
12/15/2008 1:55:03 PM
mbam-log-2008-12-15 (13-55-03).txt
Scan type: Quick Scan
Objects scanned: 75564
Time elapsed: 8 minute(s), 58 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
C:\WINDOWS\svchost.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\system\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Failed to unload process.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system\explorer.exe (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
--------------- Spybot:
Smitfraud-C.gp: [SBI $8E7F06B8] Executable (File, fixed)
C:\WINDOWS\svchost.exe
(That is all it found, I can post the whole log if you want.)
--------------- HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:39:14 PM, on 12/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system\explorer.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://Www.Wintergreensys.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} -
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} -
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} -
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) -
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} -
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 6610 bytes
Here's what happened: I downloaded Acronis True Image from a web site and Smitfraud-c.gp, Zlob and a couple other viruses came with it. I managed to clean the rest off except Smitfraud-c.gp.
I have a file named windows\system\explorer.exe which is obviously a fake explorer. I used "find" in registry for windows\system\explorer.exe and deleted the registry items it found and once again tried to delete the file itself, did not work. I booted the computer and tried to delete it with "del c:\windows\system\explorer.exe" and this did not work either. I have searched the web for hours trying to find some resolution to this and nothing seems to work. Reading through different posts trying to fix this by myself I read about Smitrem and dl'd that and ran it, but it did not fix the prob.
Here's where I'm at: Today I ran some programs I usually use to clean up harddrives. Here's the results of the scans and a HJT log:
--------------- Avast:
File name: C:\WINDOWS\SVCHOST.EXE
Malware Name: Wi????????????????e
Malware Type: Rootkit:hidden process
VPS version: 081210-0, 12/10/2008
File name: C:\WINDOWS\svchost.exe
Malware Name: Win32:Rootkit-gen [Rtk]
Malware Type: Rootkit
VPS version: 081210-0, 12/10/2008
--------------- Panda Active Scan:
ANALYSIS: 2008-12-15 11:22:41
PROTECTIONS: 2
MALWARE: 9
SUSPECTS: 2
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
avast! antivirus 4.8.1296 [VPS 081215-0] 4.8.1296 Yes Yes
iolo AntiVirus 1.5 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00122168 Application/Restart HackTools No 0 Yes No C:\WINDOWS\system32\Tools\Restart.exe
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Cookies\chris@server.iad.liveperson[2].txt
00207338 Cookie/Target TrackingCookie No 0 Yes No C:\Documents and Settings\Guest\Cookies\guest@target[1].txt
00207862 Cookie/did-it TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Cookies\chris@did-it[1].txt
00366244 Application/NirCmd.A HackTools No 0 Yes No C:\fixwareout\FindT\nircmd.exe
00520936 Application/ViewPoint HackTools No 0 Yes No C:\Program Files\Trend Micro\HijackThis\backups\backup-20080926-130701-650.dll
02916589 Application/PassRock HackTools No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP79\A0017739.exe
03738686 Generic Malware Virus/Trojan No 0 Yes No C:\SDFix\catchme.exe
03738686 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025852.exe[C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025852.exe][SDFix\apps\Cghtme.exe]
03738686 Generic Malware Virus/Trojan No 0 Yes No C:\SDFix\apps\Cghtme.exe
03738686 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025852.exe[C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025852.exe][SDFix\catchme.exe]
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025608.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025646.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP83\A0025596.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP81\A0023427.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\SDFix\backups\backups.zip[backups/svchost.exe]
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP90\A0026430.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP90\A0027468.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP90\A0027472.exe
04282197 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{4AA1BD37-FFAB-4770-A4A3-2C6BF615AE71}\RP81\A0023440.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location )5
;===================================================================================================================================================================================
No C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\ViewBar.dll )5
No C:\Program Files\Warcraft III\cdkey.exe )5
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
--------------- Housecall:
Found nothing
---------------MBAM:
Malwarebytes' Anti-Malware 1.31
Database version: 1467
Windows 5.1.2600 Service Pack 3
12/15/2008 1:55:03 PM
mbam-log-2008-12-15 (13-55-03).txt
Scan type: Quick Scan
Objects scanned: 75564
Time elapsed: 8 minute(s), 58 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
C:\WINDOWS\svchost.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\system\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Failed to unload process.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system\explorer.exe (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
--------------- Spybot:
Smitfraud-C.gp: [SBI $8E7F06B8] Executable (File, fixed)
C:\WINDOWS\svchost.exe
(That is all it found, I can post the whole log if you want.)
--------------- HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:39:14 PM, on 12/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system\explorer.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://Www.Wintergreensys.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} -
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} -
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} -
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) -
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} -
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 6610 bytes